The boot process so I don't forget it again.
Setup: There's an encrypted root partitin /, unencrypted boot partition /boot, unencrypted EFI parititon /efi
Computer is Powered On.
UEFI Firmware starts. It initializes storage controllers and discovers physical devices. Scans devices' partition tables. Looks for ESP GUID (C12A7328-F81F-11D2-BA4B-00A0C93EC93B).
The Firmware reads directory tables from the FAT ESP partition.
Check Firmware's NVRAM (A volatile memory in UEFI firmware to where OSes can write EFI files information into Variables Store region), shows them in Boot Menu. Can Boot Into them.
If NVRAM is empty, then look for a Fallback, something like /EFI/BOOT/BOOTX64.EFI, show them in Boot Menu. Boot into it.
A .EFI contains executable code for the GRUB or other bootloader(s). A bootloader is a tiny OS, separate from Linux kernel, whose job is to start the REAL OS. GRUB then reads grub.cfg from the BOOT partition. /boot/grub/grub.cfg. The menuentry sections contains descriptions for all the OSes found by grub and how to boot them. Grub has its own GRUB modules (NOT Linux Kernel modules, GRUB's and Linux's binaries are different) in /boot/grub/x86_64-efi/ that it loads with insmod command.
GRUB, loads Kernel into memory, tells it the UUID for ROOT filesystem inside root=UUID=... or cryptdevice=UUID=.... Grub writes this information into kernel's memory, then the Kernel after loading passes into initramfs. The information is also provided in userspace in /proc/cmdline. Grub jumps into the Kernel's entrypoint in Memory. The Kernel starts, Grub stops. Kernel decompresses itself, sets up memory management, interrupts, detects CPUs, initializes core subsystems, loads the Initramfs by running /init (an ash script).
Initramfs starts (/init starts running), Kernel passes root UUID to Initramfs. Initramfs sequentially runs hooks (ash scripts) (as configured in /etc/mkinitcpio.conf when building the initramfs image, and /config in the initramfs filesystem itself) that loads some Kernel modules, Prompts for LUKS password, decrypts mounts real ROOT to /new_root, switches / with /new_root. At the end of the /init script, it calls the binary /sbin/init. Which is the OS's actual Init software that then starts all userspace services.
Notes:
1. Use lsinitcpio to list initramfs file contents and -x to decompress the initramfs .img file.
2. EFI files use PE executable format (Yes, Window's PE executable)
3. UEFI Firmware apart from /EFI/BOOT/BOOTX64.EFI try to look for /EFI/Micro(slop)soft/Boot/bootmgfw.efi (Boo), as a default fallback address for EFI files!
4. UEFI firmware itself is like a small kernel that provides kernel-like features and an API that Bootloader uses to boot into the real OS.
5. Some UEFI firmware might be bricked (unsure) because they do not save Boot list into nvram variables. The only way for the firmware to detect the files is to store them in a fallback location.